Skip to main content
Security

Kimi K3 exploited the latest Redis server

Moonshot AI’s Kimi K3 reportedly helped researchers uncover Redis vulnerabilities and build remote code execution exploits. Image: Primary
A security team using Moonshot AI's Kimi K3 said one of its agents found a Redis flaw and built a working remote code execution exploit in 27 minutes, according to a report published Thursday. The researchers published authenticated proof-of-concept exploits targeting Redis versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0, with both attack paths requiring access to the RESTORE command. Redis issued seven security updates on July 23 to address the underlying memory-corruption flaws. Fixed versions were released across supported branches, including 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5, and 8.8.1. Neither Redis' July 23 release notes nor the public proof-of-concept repositories reported exploitation in the wild as of July 24. The first attack path involved a shared-ownership flaw in Redis Streams, while the second affected the RedisBloom TDigest loader. The published scripts were designed to turn memory errors into arbitrary read-and-write access and eventually execute system commands. CyberPress said the Kimi K3 agent cloned the Redis source code, fuzzed selected functions, and used the GDB debugger with limited human guidance. The reported 27-minute exploit-development time and a separate claim that Kimi K3 agents found 19 Redis zero-days in about 90 minutes remain self-reported. Redis confirmed the underlying flaws and released fixes but did not verify how independently the agents worked or validate the claimed number of discoveries.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from eweek.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Chrome 153 fixes actively exploited V8 flaw

Google released Chrome 153 to the stable channel with fixes for 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine. Google says an exploit for the medium-severity...

Infrastructure AI
Infrastructure AI

1NCE launches benchmarking and unified AI access for IoT customers

1NCE announced an upgrade to its Insights service and the launch of 1NCE AI. Insights gives customers access to aggregated benchmark data from more than 30,000 deployments for comparisons of network usage, battery performance, har...

Security
Security

Microsoft fixes 974 flaws, including two exploited Windows zero-days

Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppCont...

Security
Security

N-able issues hotfix for N-central zero-day

N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...